Template content. Review and adapt with qualified legal counsel before publication. Every bracketed value must be replaced.
Effective date: [EFFECTIVE DATE]
Last updated: [LAST UPDATED DATE]
01Who we are
This policy is issued by [LEGAL ENTITY NAME] (“CyberSecOps”, “we”, “us”), registered at [REGISTERED ADDRESS]. It applies to cybersecops.dev and to personal information we handle when providing services to our clients.
For privacy questions, contact [PRIVACY CONTACT EMAIL]. Where required by law, our data protection representative is [DATA PROTECTION OFFICER OR REPRESENTATIVE].
02Information we collect
We collect the information you give us directly and a limited amount of technical information generated when you use this site.
- Contact and enquiry details you submit: name, work email address, organization, region and the content of your message
- Correspondence, including email and meeting records relating to an enquiry or engagement
- Technical data such as IP address, browser type, device type, referring page and pages viewed
- Client environment information processed under a services agreement, on the instructions of that client
We do not ask for special-category personal data through this website, and we ask that you do not include it in enquiry messages.
03How we use information
We use personal information to respond to enquiries, to scope, deliver and support engineering services, to manage our contractual and business relationships, to secure and improve this website, and to meet our legal and regulatory obligations.
We do not sell personal information, and we do not use enquiry details for unrelated marketing without a separate, clearly given consent.
04Legal bases
Where [APPLICABLE DATA PROTECTION LAW] requires a legal basis, we rely on: performance of a contract or steps taken at your request before entering one; our legitimate interests in operating and securing our business, balanced against your rights; compliance with a legal obligation; and consent, where consent is the appropriate basis. Consent may be withdrawn at any time.
05Service providers and disclosure
We share personal information with vetted providers who support our operations — for example hosting, communications, and business administration — under contracts that restrict their use of it to our instructions.
We may also disclose information where required by law, to establish or defend legal claims, or in connection with a corporate transaction, subject to appropriate safeguards. A current list of categories of processors is available on request from [PRIVACY CONTACT EMAIL].
06International transfers
Where personal information is transferred outside [PRIMARY JURISDICTION], we put in place a recognized transfer mechanism such as standard contractual clauses, together with technical measures appropriate to the sensitivity of the data.
07Retention
We keep enquiry correspondence for [ENQUIRY RETENTION PERIOD] unless it becomes part of a client relationship, in which case records are retained for the duration of the engagement plus [CLIENT RETENTION PERIOD] to meet contractual, tax and legal requirements. Client environment data is retained and deleted according to the terms of the applicable services agreement.
08How we protect information
We maintain technical and organizational measures appropriate to the risk, covering access management, encryption in transit and at rest, secrets management, endpoint protection, logging and monitoring, and a documented incident response process.
[CONFIRM THIS LIST MATCHES THE CONTROLS YOU ACTUALLY OPERATE BEFORE PUBLICATION — a privacy policy is an enforceable representation, not a statement of intent.]
No system is perfectly secure. If a breach affects your personal information and the law requires notification, we will notify you and the relevant supervisory authority within the required timeframe.
09Your rights
Subject to the law that applies to you, you may request access to your personal information, correction of inaccurate data, deletion, restriction of or objection to processing, and portability. Where we act as a processor for a client, we will refer your request to that client and support their response.
To exercise a right, contact [PRIVACY CONTACT EMAIL]. We will verify your identity before acting, and respond within the period required by [APPLICABLE DATA PROTECTION LAW]. You may also complain to your supervisory authority, [SUPERVISORY AUTHORITY].
10Cookies and analytics
This site uses strictly necessary cookies to function, and [ANALYTICS PROVIDER, OR “no analytics cookies”] to understand aggregate usage. Non-essential cookies are set only after you consent.
To change or withdraw a cookie choice, or to ask what is set on your device, contact [PRIVACY CONTACT EMAIL]. [IF YOU DEPLOY A CONSENT BANNER, REPLACE THIS SENTENCE WITH A LINK TO ITS PREFERENCES CONTROL.]
11Children
This website and our services are directed at organizations and are not intended for children. We do not knowingly collect personal information from anyone under the age of [MINIMUM AGE].
12Changes to this policy
We update this policy when our practices or legal obligations change. Material changes will be highlighted on this page, and the effective date above will be revised.
13Contact us
Questions about this policy, or about how we handle personal information, can be sent to [PRIVACY CONTACT EMAIL] or by post to [REGISTERED ADDRESS]. Suspected security vulnerabilities should instead be reported to security@cybersecops.dev.